I just ran the latest version of RKHunter against my 6.0.1-01 box and it found the following vulnerabilities.
GnuPG 1.0.7
Apache 1.3.27
OpenSSL 0.9.6b
ProFTPd 1.2.9
Since there hasnt been an update in close to a year, I knew I would have vulnerabilities and likely does beyond the brief list above, but I tried to suppress my concern by watching the logs.
Now that RKHunter has 'reopened' my eyes if you will, I am curious if there is a contrib, or a howto that will teach me what versions I need to download and complile for each of these. Obviously I can download the source and compile, but SME 6 doesnt exactly come with the source dev compilers installed by default. Do I need an old RH 7.3 machine?
Can anyone send me in the right direction on how to get these holes patched? I'll be happy to share what I build with the community as an unofficial patch or whatever, but I honestly dont know where to begin.
Thanks